Two-Key Breach Could Hand Hackers Control of $91 Billion in USDT, Security Assessment Finds
Key Takeaways
- •Bluechip raised Tether's rating from D to C following a financial audit by KPMG US, its first review under a new system pairing financial analysis with Hacken's cybersecurity scoring.
- •Hacken scored USDT only 3.3 out of 10 on cybersecurity, finding that about $91.3 billion of the token on Tron is governed by administrative controls requiring just two signing keys.
- •The USDT contract on Tron lacks a timelock, delay, or cancellation process, so a two-key compromise would allow minting, freezing addresses, and redirecting balances without accessing individual wallets.
- •Tether reuses the same six signing keys across Ethereum, Avalanche, and Celo, meaning a compromise on one network could enable administrative actions on another.
- •Hacken has not yet assessed Circle's USDC under the new methodology, so Bluechip's B+ USDC rating is not directly comparable.

Roughly half of all circulating USDT — about $91.3 billion on the Tron network — is governed by a contract whose administrative controls can be seized by anyone holding two signing keys, with no built-in delay, cancellation window, or way to reverse the change, according to an assessment by blockchain security firm Hacken.
Although the world's largest stablecoin scored only 3.3 out of 10 on cybersecurity, rating company Bluechip raised issuer Tether's corporate grade from D to C, following a financial audit by KPMG US, one of the Big Four global auditing firms. Tether is the first company reviewed by Bluechip under a new system that pairs a financial review with analysis by Hacken. The review found no evidence that any key has been compromised or that any security incident has occurred.
The multisig in question does not hold user funds; it controls the USDT contract itself — the power to mint tokens, freeze addresses, and reassign ownership. That is why a two-key compromise would allow an attacker to act across the entire deployment without touching any individual wallet. In practice, many major DeFi and token contracts mitigate this class of risk with timelocks — enforced waiting periods between a proposed administrative change and its execution — which give the community a window to react or withdraw before changes take effect. According to Hacken's assessment, the USDT contract on Tron has no such mechanism.
"There is no built-in delay, cancellation process, or reliable way to undo the changes," Seher Saylık, a smart contract auditor at Hacken, told CoinDesk via Telegram.
Tether did not immediately respond to a request for comment.
The distinction matters beyond Tether. Stablecoins like USDT sit at the center of crypto trading and lending, so the integrity of their contract administration is a form of systemic infrastructure risk for the broader market, separate from whether an issuer's reserves are fully backed. A grading system that now combines financial audits with technical security scoring — as Bluechip's new methodology does — reflects that dual nature of stablecoin risk.
Hacken said it has not yet completed a comparable assessment of Circle's USDC. Bluechip's B+ rating for USDC therefore cannot be treated as a direct technical comparison, as it was assigned under Bluechip's earlier methodology, before Hacken's cybersecurity factor was introduced. A future Hacken assessment of USDC would make an apples-to-apples technical comparison possible for the first time under the new system.
According to Saylık, an attacker could first change the contract owner to an address they control, locking out Tether's legitimate signers. The attacker could then mint USDT, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee, or redirect token balances and transfers — all without needing access to individual users' wallets.
"The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not," said Leo Fan, founder and CEO of Cysic.xyz and former lead on quantum resilience at Algorand. "Half the supply, about $91 billion on Tron, still sits behind two keys with no timelock and nothing onchain seems to impede what those keys can mint tomorrow."
The same risk can extend across Ethereum, Avalanche, and Celo, because Tether reuses the same six signing keys across all three networks, Saylık said. A compromise involving keys used on Celo or Avalanche could also be used to authorize a separate administrative transaction on Ethereum.
Source: CoinDesk